瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 牛X病毒 瑞星系列软件无法执行 高手进来

12   2  /  2  页   跳转

牛X病毒 瑞星系列软件无法执行 高手进来

早看完了```

8楼里``

上面说的那些都可以想办法删除他们```

SRENG操作方法:
http://hi.baidu.com/%B9%C2%B6%C0%B8%FC%BF%C9%BF%BF/blog/item/9025a818a7592ab44aedbc05.html
gototop
 

360清理了大量流氓软件和木马出来
用瑞星注册表恢复工具恢复后
还是无效
试了试卡巴 跟瑞星一样也启动不起来~~~
gototop
 

[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rxso0.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qjso0.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ztso1.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\woso0.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mhso0.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wlso0.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tlso0.dll] [N/A, ]
先把这个搞掉 杀毒软件才能打开
gototop
 

注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
    <bgswitch><C:\WINDOWS\system32\bgswitch.exe>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [N/A]
    <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
    <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
    <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <nwiz><nwiz.exe /install>  [N/A]
    <NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <C-Media Mixer><Mixer.exe /startup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <wdsa><C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wdso.exe>  [N/A]
    <Thunder><"C:\Program Files\Thunder Network\Thunder\Thunder.exe" /s>  [Thunder Networking Technologies,LTD]
    <WSVBRS><C:\WINDOWS\WSVBRS.exe>  []
    <apqkqli><C:\WINDOWS\system32\pgijhph.exe>  []
    <ipsaofj><C:\WINDOWS\system32\epiaumj.exe>  []
    <360Safetray><D:\Program Files\360safe\safemon\360tray.exe>  [奇虎网]
    <AVP><"D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe">  [Kaspersky Lab]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    <visin><C:\WINDOWS\system32\ctfnom.exe>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
    <WinlogonNotify: klogon><C:\WINDOWS\system32\klogon.dll>  [Kaspersky Lab]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><C:\WINDOWS\system32\bubbles.scr>  [Microsoft Corporation]
注册表补上
gototop
 

[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rxso0.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qjso0.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ztso1.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\woso0.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mhso0.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wlso0.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tlso0.dll] [N/A, ]
先把这个搞掉 杀毒软件才能打开
上面的文件已经没有了
gototop
 


[Provisioning Service / Provisioning Service][Stopped/Auto Start]
<C:\WINDOWS\expl0rer.exe><N/A>

[R2A / R2A][Stopped/Disabled]
<\??\C:\WINDOWS\system32a2.sys><N/A>
[Bluesky / Bluesky][Running/]
<2 - 系统找不到指定的文件。
><N/A>
[lgjgre / lgjgre][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\drivers\lgjgre.sys><N/A>

[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\upxdnd.dll] [N/A, ]
[C:\WINDOWS\system32\nwizAsktao.dll] [N/A, ]
[C:\WINDOWS\system32\czhtpp.dll] [N/A, ]
[C:\WINDOWS\system32\moyu102.dll] [N/A, ]
[C:\WINDOWS\system32\nwizwmsjs.dll] [N/A, ]
[C:\WINDOWS\system32\cmdbcs.dll] [N/A, ]
[C:\WINDOWS\system32\nwizqjsj.dll] [N/A, ]
[C:\WINDOWS\system32\mppds.dll] [N/A, ]
[C:\WINDOWS\system32\nwizhx2.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ztso0.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rxso0.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\woso1.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qjso0.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mhso1.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wlso1.dll] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tlso1.dll] [N/A, ]
[C:\WINDOWS\system32\czhtpp.dll] [N/A, ]
[C:\Program Files\Internet Explorer\PLUGINS\System64.sys] [N/A, ]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\packet.dll] [CACE Technologies, 3, 1, 0, 27]
[C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WanPacket.dll] [CACE Technologies, 3, 1, 0, 27]
[C:\Program Files\Media Player Classic\Codecs\mmfinfo.dll] [N/A, ]
[C:\Program Files\Media Player Classic\Codecs\mkunicode.dll] [N/A, ]
[C:\PROGRA~1\3721\autolive.dll] [, 2, 5, 3, 1007]
[C:\PROGRA~1\3721\alLiveEx.dll] [ , 1, 0, 3, 1006]

Autorun.inf
[E:\]
[AutoRun]
open=ipsaofj.exe
shell\open=打开(&O)
shell\open\Command=ipsaofj.exe
shell\open\Default=1
shell\explore=资源管理器(&X)
shell\explore\Command=ipsaofj.exe
gototop
 

【回复“newcenturymoon”的帖子】


为什么  ??
gototop
 

我顶~~~~
gototop
 

再顶~~
召唤孤独 和众老鸟
gototop
 

有ipsaofj.exe病毒专杀,你可以下载
http://mumayi1.999kb.com/pic/2007-06-05/4k83uu9kzgvbvug6bx24.zip
gototop
 
12   2  /  2  页   跳转
页面顶部
Powered by Discuz!NT